VulnSea

ThemeMove has 4 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 7.8 (high). The most common weakness class is CWE-98 (3).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
—
Last 90 days
1 prev 0

Weakness classes

Products

  • edumall 1
  • minimogwp 1
  • mitech 1
  • moody 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ThemeMove vulnerabilities

CVEs affecting ThemeMove, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-39748High· 7.1
today

Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions.

Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions.

▾ TwilightThemeMove · edumallvia NVD
CVE-2025-22708High· 8.1
9mo ago

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.This issue affects Mitech: from n/a through <= 2.3.4.

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.This issue affects Mitech: from n/a through <= 2.3.4.

▾ Twilightthememove · mitechEPSS 0.57%via NVD
CVE-2025-22707High· 8.1
9mo ago

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.This issue affects Moody: from n/a through <= 2.7.3.

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.This issue affects Moody: from n/a through <= 2.7.3.

▾ Twilightthememove · moodyEPSS 0.57%via NVD
CVE-2025-68062High· 7.5
9mo ago

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.

▾ Twilightthememove · minimogwpEPSS 0.36%via NVD
ThemeMove vulnerabilities (CVEs) · VulnSea